Private US Companies Now Approved to Run Cyber Operations Abroad (With Restrictions)
Private US companies can now conduct offensive cyber operations abroad, under a presidential memorandum signed by Donald Trump on August 12, 2026, and published by the White House that night. The memo, which is five sections long, allows vetted firms to target foreign criminal groups engaged in cyber-enabled transnational crime, but excludes state-backed hackers.
Key Points:
-
National Coordination Center: A new center will create and oversee the program, with two Program Executive Directors appointed by the Attorney General and Secretary of Homeland Security.
-
Rationale: The memo states that transnational criminal organizations pose a significant threat to American citizens, businesses, and national security. It emphasizes the underutilized capabilities of US businesses in disrupting these networks.
-
Targeted Threats: According to the White House fact sheet accompanying the memo, Americans lost $20.8 billion to cybercrime in 2025, with 73% experiencing online scams or attacks and 98% perceiving them as a threat to the nation. Vulnerable populations include seniors, children, and low-income families facing ransomware, phishing, fraud, and sextortion.
-
Authorized Operations:
- Cyber Surveillance Operations: These involve collecting intelligence by accessing systems unauthorized, with the goal of remaining undetected.
- Cyber Effects Operations: These aim to manipulate, disrupt, or damage information systems, networks, or infrastructure.
-
Exclusions: The memo defines eligible targets as "any foreign group that conducts cyber-enabled crime" against US interests. It explicitly excludes groups that are an institutional part of a foreign government or operate wholly under its direction—a move that specifically targets North Korean hackers and some Eastern European gangs allegedly operating with Russian consent.
-
Not Hack Back: While the memo is sometimes described as a "hack back" authorization, it stops short of allowing companies to launch attacks independently. These operations will be conducted under federal contract and supervision. The longstanding US policy remains that private firms may defend against cyberattacks but not initiate them.